|
269131
|
- |
|
zohocorp
|
manageengine_opmanager
|
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7766
|
2024-11-21 11:37 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269132
|
- |
|
zohocorp
|
manageengine_opmanager
|
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access …
|
NVD-CWE-Other
|
CVE-2015-7765
|
2024-11-21 11:37 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269133
|
- |
|
apple
|
mac_os_x
|
Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecified action during the printing of an e-mail message…
|
CWE-200
Information Exposure
|
CVE-2015-7761
|
2024-11-21 11:37 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269134
|
- |
|
apple
|
mac_os_x
|
libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which allows remote attackers to cause a denial of service (resource consumption) by …
|
CWE-399
Resource Management Errors
|
CVE-2015-7760
|
2024-11-21 11:37 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269135
|
- |
|
google
|
android
|
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different …
|
NVD-CWE-noinfo
|
CVE-2015-7718
|
2024-11-21 11:37 |
2015-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269136
|
- |
|
google
|
android
|
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7717
|
2024-11-21 11:37 |
2015-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269137
|
- |
|
google
|
android
|
libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 2072105…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7716
|
2024-11-21 11:37 |
2015-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269138
|
- |
|
cisco
|
vpn_client
|
Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the Applica…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7600
|
2024-11-21 11:37 |
2015-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269139
|
- |
|
email-address_project
|
email-address
|
Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial of service (CPU consumption) via a crafted string c…
|
CWE-20 CWE-399
Improper Input Validation Resource Management Errors
|
CVE-2015-7686
|
2024-11-21 11:37 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269140
|
- |
|
arkeia
|
western_digital_arkeia
|
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted req…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7709
|
2024-11-21 11:37 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|